<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Android rejecting ISE's publicly-signed certificate? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238976#M160371</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agree with Mohit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly review the attached.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 May 2013 11:38:21 GMT</pubDate>
    <dc:creator>manjeets</dc:creator>
    <dc:date>2013-05-20T11:38:21Z</dc:date>
    <item>
      <title>Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238970#M160313</link>
      <description>&lt;P&gt;We have recently deployed a VeriSign certificate on ISE for both HTTPS and EAP, it uses a corporate CA to generate and push out user certs. It seems to work on all devices but Android.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Android device successfully completes onboarding process, but when it tries to connect using EAP-TLS, it fails and the following error shows on the ISE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Authentication failed: 12520 EAP-TLS filed SSL/TLS handshake because the client rejectd the ISE local-certificate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been verified that VeriSign's root certificate has been pushed out and installed on the Android devices. I can't understand why would the client not trust validate the VeriSign certificate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before? Does the client need a corporate root certificate chain to trust the user certificate it has been privisoned with? Could that be the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ISE is running v1.1.3 patch 1&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238970#M160313</guid>
      <dc:creator>zmainedsnz</dc:creator>
      <dc:date>2019-03-11T03:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238971#M160320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;Hi &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;The error message means:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;This is an indication that the client does not have or does not trust the Cisco ISE certificates. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 
 For both the client/server certs, If&amp;nbsp; there are multiple levels&amp;nbsp; in the cert chain (Intermediate certs) and if so, you need to make sure that intermediate 
certs been installed in ISE and in the client machine as well.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt; - Could you provide me the model and make of the supplicant, you&amp;nbsp; have been facing issue with? Is it Android &lt;STRONG&gt; 4.1.x&lt;/STRONG&gt;. Also is it happening with justone client or with all of the clients?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;PRE&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;I would strongly suggest you to install all the chain certs in both ISE and CLIENT ,test it and let me know if it helped.&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial black,avant garde; color: #333333; font-size: 12pt;"&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;Minakshi (Do rate the helpful posts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; )&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 00:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238971#M160320</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-05-07T00:57:50Z</dc:date>
    </item>
    <item>
      <title>Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238972#M160327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Do we know which side has the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we migrated from a full internal CA configuration and the ISE has all the trusted root certs of internal CAs. I am drawing the conclusion that it is the client side rejecting the ISE cert. But it has been verified the VeriSign Cert did get pushed out and I thought even nothing got pushed out, VeriSign cert would still work due to its wide support?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, the fact that it works on iOS makes me think it is an Android specific issue. Will get back to do more checks along the chain. Is there a way to push out the internal trust chain together with the VeriSign trust chain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 01:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238972#M160327</guid>
      <dc:creator>zmainedsnz</dc:creator>
      <dc:date>2013-05-07T01:21:53Z</dc:date>
    </item>
    <item>
      <title>Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238973#M160336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Error states the client couldn't trust the policy service node certificate. Since it's working for other supplicant's and just not with android, we need to look down first at supplicant side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the error, we need to ensure that the certificate authority that signed this server certificate is correctly installed in client's supplicant. You wrote:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;It has been verified that VeriSign's root certificate has been pushed out and installed on the Android devices. &lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Let's set the runtime-aaa and runtime-config logs at debug level under administration || logging || debug log configuration --- Save it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reproduce the issue from the android supplicant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Operation || troubleshoot || download logs || tick only&lt;/P&gt;&lt;P&gt;Include debug logs&lt;/P&gt;&lt;P&gt;Include monitoring and reporting logs&lt;/P&gt;&lt;P&gt;Include most recent file = 1&lt;/P&gt;&lt;P&gt;Add the encryption key&lt;/P&gt;&lt;P&gt;Generate the bundle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 01:28:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238973#M160336</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T01:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238974#M160348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt;"&gt;Hi &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt;"&gt;&amp;nbsp; Did you install the whole chain on the client as well? Coz the issue looks like to be on the client side, also, if you could give me the android version as well which is causing issue? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt;"&gt;Do test the authentication after installing the chain certificates on the client and see if that resolves the issue.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt;"&gt;Minakshi (Do rate the helpful posts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 20:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238974#M160348</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-05-07T20:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238975#M160359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the android OS version you are using, and refer following. Afterwards take the action accordingly.&lt;/P&gt;&lt;P&gt;&lt;IMG /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/4/8/138840-Android.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 11:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238975#M160359</guid>
      <dc:creator>mojuneja</dc:creator>
      <dc:date>2013-05-08T11:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Android rejecting ISE's publicly-signed certificate?</title>
      <link>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238976#M160371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agree with Mohit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly review the attached.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 May 2013 11:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/android-rejecting-ise-s-publicly-signed-certificate/m-p/2238976#M160371</guid>
      <dc:creator>manjeets</dc:creator>
      <dc:date>2013-05-20T11:38:21Z</dc:date>
    </item>
  </channel>
</rss>

